Security

Stillian Verifies Blocking of AI Agent-Based Web and API Attacks with “WebSuit”

TECHWORLD ·

Stealien confirmed that Websuite's in-house testing blocked web and API attacks based on AI agents. [Photo: Stealien]

✦ Resumen de IA

Stillian said on the 6th that it had conducted an internal test of its AI-based web security solution, WebSuit.

The internal test examined whether WebSuit could respond to attack flows in which an AI autonomous penetration testing tool discovers web service API information and then carries out browser automation.

As a result, WebSuit was verified to block API reconnaissance and browser automation, and blocking was also confirmed in curl and Playwright access attempts.

Stillian said on the 6th that it had conducted an internal test of its AI-based web security solution, WebSuit. Using an AI autonomous penetration testing tool, Stillian tested attack flows that move from web service API information discovery to browser automation, and checked whether WebSuit would respond.

The verification targeted attack flows recently abused in incidents, including ARTEX, a Chinese-language AI penetration testing tool. Stillian carried out its own test against those flows.

As a result of the internal test, WebSuit was verified to block API reconnaissance used in AI agent-based attacks, and browser automation used in AI agent-based attacks was also verified to be blocked. Stillian confirmed WebSuit’s blocking in an API reconnaissance attempt using the command-line tool curl, and also in an access attempt using the browser automation tool Playwright.

WebSuit has features that dynamically change API paths to randomize them, as well as request-and-response encryption. The company said the internal test showed that this randomization and encryption made it difficult to analyze the service call structure and data, demonstrating blocking performance.

The server-side roles are authentication token verification, data tampering checks, and allow-or-block decisions. By verifying tokens and data integrity, the server determines whether to allow requests, thereby countering attacks that analyze or manipulate requests based on fixed API paths and plaintext parameters.

As a defense against AI agent-based attacks, AI behavior analysis and PoW (proof-of-work) challenges are used. In this process, automated attack patterns such as mouse movements, clicks, input, and scrolling, as well as the browser execution environment, are analyzed to identify abnormal access.

Suspicious requests are assigned computational tasks. This increases the time and resource burden required for an attack attempt and, as a result, suppresses the threat.

This approach also extends to credential stuffing countermeasures. Credential stuffing is a method of repeatedly entering stolen account information, and the response technologies used are token verification and automation detection. This limits abnormal login attempts and adds further verification burden to automated requests used in bypass attempts, curbing large-scale attempts.

The application method for each customer environment can be configured in stages, from monitoring to verification to blocking. The level of enforcement is adjusted step by step to fit the customer’s environment.

Kim Byeong-cheol, head of Stillian’s Solution Business Division, said that to respond to attacks using AI agents, it is necessary to verify defense effectiveness at each stage of service structure discovery and request execution. He added that based on attacker-perspective research and verification, the company plans to continue advancing web and API protection technologies that can be applied to customers’ real-world services.

Source: TECHWORLD · Lee Gwang-jae
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407775

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

Ver original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.